CSIDB logo
Threat actor

Shadow Kill Hackers

Attribution profile

Type
Criminal
Location
China
Known incidents
2 incidents
First seen
2019-07-25
Last seen
2019-10-24
Updated
2026-07-31 21:44
Aliases
3 aliases

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

Shadow Kill Hackers, also known as Shadow Kill Group and Shadow Hackers, is a threat actor that has been observed conducting ransomware operations. Open‑source reporting indicates that the group is believed to operate from China, although no definitive public attribution to a state sponsor has been made. The actor uses multiple aliases in underground communications and in ransom notes, which helps obscure its identity across different incidents. Despite the limited public detail, the consistent use of the Shadow Kill moniker links the separate activities attributed to this actor. This naming pattern allows analysts to track the group's evolution over time.

The group’s known victims include municipal government entities and essential service providers in Johannesburg, South Africa. In October 2019 the City of Johannesburg’s website and billing systems were taken offline after a ransomware intrusion, with the attackers demanding four Bitcoins, then valued at roughly thirty thousand dollars. A few months earlier, in July 2019, a major electricity supplier in the same city suffered a similar ransomware event that encrypted databases, applications and network components, disrupting prepaid electricity sales and hindering responses to local blackouts. Both incidents resulted in service interruptions but officials confirmed that no customer data was exfiltrated or compromised. The repeated focus on public‑facing infrastructure suggests a financially motivated strategy aimed at extorting payment for restoration.

Technical descriptions of the attacks highlight the use of ransomware that encrypts critical systems and demands payment in Bitcoin to regain access. No specific malware family or toolset has been publicly named in the reporting, so the actor’s tooling style remains unspecified beyond the observed encryption and ransom note behavior. Initial access vectors were not disclosed in the available sources, leaving the method of compromise unknown. The actor’s affiliation with any criminal consortium or state apparatus has not been established, and attribution remains based solely on geographic inference. Consequently, the Shadow Kill Hackers are presently characterized as a ransomware‑focused group with demonstrated capability to disrupt municipal and utility services in South Africa for financial gain.

Incidents

Attributed incidents are available to members.

2 incidents
CSIDB